Falhas do tipo CWE-400

3.026 resultados

Consumo não controlado de recursos

A aplicação não limita adequadamente o consumo de recursos (memória, CPU, conexões, disco) em resposta a requisições ou eventos, permitindo que um atacante esgote os recursos disponíveis. Resultado: negação de serviço, travamento ou crash da aplicação.

Exemplo

Um servidor web que aceita uploads sem limite de tamanho permite que um atacante envie um arquivo gigante, preenchendo o disco e derrubando o serviço. Outro cenário: aceitar conexões TCP indefinidamente sem timeout, até esgotar o número máximo de sockets do sistema operacional.

Como mitigar

Implemente limites explícitos: tamanho máximo de requisição/arquivo, timeout de conexão, limite de memória por processo, rate limiting. Use filas com capacidade máxima e rejeite requisições excedentes com mensagem de erro clara (HTTP 429, por exemplo).

CVE-2026-84289MEDIUMNousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocationEPSS 0.5%CVE-2026-33474MEDIUMVikunja Affected by DoS via Image Preview GenerationEPSS 0.5%CVE-2025-53538HIGHSuricata's mishandling of data on HTTP2 stream 0 can lead to resource starvationEPSS 0.5%CVE-2026-84888MEDIUMRightNow-AI OpenFang tool_runner.rs shell_exec memory allocationEPSS 0.5%CVE-2025-68971MEDIUMIn Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be asEPSS 0.5%CVE-2026-6601MEDIUMLagom WHMCS Template Datatables resource consumptionEPSS 0.5%CVE-2024-34364MEDIUMEnvoy OOM vector from HTTP async client with unbounded response buffer for mirror responseEPSS 0.5%CVE-2026-40924MEDIUMTekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory ExhaustionEPSS 0.5%CVE-2026-46862HIGHVulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.EPSS 0.5%CVE-2026-46835HIGHVulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploEPSS 0.5%CVE-2026-87222HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2026-83225HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.5%CVE-2026-83222HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.5%CVE-2026-70908HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.5%CVE-2026-87215HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2026-60301HIGHVulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.EPSS 0.5%CVE-2026-34290HIGHVulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that iEPSS 0.5%CVE-2026-87199HIGHVulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is EPSS 0.5%CVE-2026-83183HIGHVulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affEPSS 0.5%CVE-2026-73882HIGHVulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected aEPSS 0.5%